Vulnerability disclosure
If you find a potential vulnerability in kastro.is or a Kastro product, email andri@kastro.is. Reports are received by Andri Pétur Hafþórsson.
Identify the affected website or product, explain how to reproduce the issue and describe its potential impact. Use synthetic data in examples and remove passwords, access tokens and personal information before sending evidence.
Limit testing to your own accounts and data. Do not access or modify other people’s data, disrupt services or use social engineering. This page does not authorise testing of third-party systems.
Please contact us before publishing technical details so the issue can be assessed and disclosure coordinated with remediation.